CVE-2026-32108 is a medium-severity vulnerability in Copyparty versions prior to 1.20.12, stemming from a missing permission check in its shares feature when utilizing FTP or SFTP. This flaw allows an authenticated user browsing a single-file share via FTP/SFTP to gain unauthorized read access to other sibling files within the same directory by guessing filenames. With a CVSS score of 6.5, the vulnerability has a high impact on confidentiality, as it enables remote access to potentially sensitive data. There is currently no evidence of active exploitation, public exploit code, or significant community discussion for this CVE. Organizations are advised to upgrade Copyparty to version 1.20.12 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.20.12CPE matchmatch criteria | cpe:2.3:a:9001:copyparty:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.